CPA · CISA · CISM · CDPSE · CCSE · MBA
A board meeting in a glass-walled room, directors with laptops and papers facing the chair

Corporate Governance Advisory for Boards and Private Companies

Governance frameworks, board and committee structure, delegation of authority and the reporting a board needs to oversee management credibly.

When does a private company need corporate governance advisory in California?

Usually at one of three moments: an outside investor joins the board and asks questions nobody has documented answers to, a fraud loss reveals that one person could both initiate and approve the same payment, or an acquirer's diligence team asks for a delegation of authority matrix that does not exist. The work is board and committee structure, delegation of authority, and reporting a board can genuinely oversee management with.

Corporate governance advisory in California is not paperwork, and it is not a compliance exercise borrowed from public companies. It is the set of arrangements that let a board know whether management's account of the business is true, and let management act decisively without the board discovering things after the fact.

For a private company that has never needed any of it, the practical test is not whether the arrangements look impressive in a binder. It is whether a director can establish, without asking management to confirm it, that the controls they are relying on exist and are working.

What corporate governance advisory in California actually delivers

Stripped of the language, five things:

  • Decision rights. Who can commit the company to what, at what value, and who must approve. Written down, matched to actual system permissions, and reviewed when people change roles.
  • Board and committee structure. What the board decides versus what it oversees; whether an audit committee is warranted and what its charter says; how often it meets and what it receives beforehand.
  • Information flow. What management reports, how often, at what level of detail, and (critically) how bad news reaches the board without passing through the person responsible for it.
  • Risk oversight. An agreed statement of what risks the company is prepared to accept, with the ones outside that appetite escalated rather than absorbed.
  • Accountability mechanisms. Whistleblowing routes, conflict-of-interest declarations, related-party transaction approval, and a process for handling an allegation involving a senior person.

Most private companies have some of this informally. The value of writing it down is not bureaucratic; it is that informal arrangements fail exactly when they are needed, which is when the person who held them in their head is the subject of the question.

Governance for companies without a formal board

Plenty of companies in Ventura County and Los Angeles County are owner-managed with a nominal board that meets once a year to sign resolutions. Governance advisory is still relevant, but the framing changes from board oversight to operating discipline.

The questions become concrete. Who can change a supplier's bank details, and does anyone verify the change by a channel other than the email that requested it. Who reviews the bank reconciliation, and is it the same person who prepares it. What happens if the founder is unreachable for three weeks. Who has administrative access to the accounting system, and when was that list last examined.

These sound operational because they are. They are also, in aggregate, the governance framework of a company that does not think it has one, and each of them corresponds to a loss that a comparable company somewhere has already suffered.

Audit committee support

Audit committees in mid-market companies are frequently composed of directors with real commercial experience and no assurance background. They are asked to evaluate the external auditor, form a view on management's judgments, oversee the internal control environment, and respond to whistleblower reports, without a technical adviser of their own.

Support here typically covers charter drafting, an annual work plan mapped to the reporting calendar, preparation for the auditor's required communications and what the committee should probe in them, independent review of significant accounting judgments, and briefing on matters where the committee's obligations differ from management's.

Having spent twenty years on the auditor's side of that table informs what is actually useful: the questions that reliably surface a problem, and the answers that sound reassuring but are not.

Technology and AI on the board agenda

Boards are increasingly expected to oversee cybersecurity and, now, AI adoption, usually without anyone in the room who can evaluate what they are being told. The result is a briefing that either alarms without informing or reassures without evidence.

Practical oversight is narrower than the topic suggests. For cybersecurity: what would a material incident actually cost this company, which third parties hold our data, what is the actual recovery time rather than the target, and when was that last tested. For AI: where is it in use, what data goes into it, who validated the output before it was relied upon, and what is the position if a customer asks whether their data trained a model.

Because this practice also performs the underlying cybersecurity risk assessment work, the board briefing is grounded in what the assessment found rather than in generic risk language.

The independence boundary

Governance advisory and assurance cannot be performed by the same party on the same subject matter. An advisor who designs a control framework cannot then provide an objective opinion on whether it works, and any firm offering both on the same engagement is offering you a compromised outcome.

Both services exist here, and the boundary is agreed in writing at the start. Where this practice designs, the testing goes elsewhere. Where this practice tests (see internal controls assessment) the design work belongs to management or another advisor.

Javed Peeran CPA

Javed Peeran

CPA · CISA · CISM · CDPSE · CCSE · MBA

Licensed by the California Board of Accountancy and the author of every article published here. Thirty years of practice covering external audit of banks, insurers and mortgage companies, fifteen years as CFO and Corporate Controller inside technology companies, and IT governance and security compliance work spanning SOX 404, SOC 1 and SOC 2, ISO 27001, FISMA, FedRAMP, PCI DSS, HIPAA/HITECH, CCPA and GDPR, plus Oracle ERP migrations and, more recently, generative-AI audit automation.

What the engagement delivers

  • Governance framework assessment against company size, ownership and risk profile
  • Delegation of authority matrix, reconciled to actual system permissions
  • Board and committee charters, including audit committee terms of reference
  • Board reporting pack design and information flow review
  • Risk appetite statement and escalation thresholds
  • Conflict of interest, related-party and whistleblowing policies with a workable process behind them
  • Audit committee annual work plan and pre-meeting briefings
  • Board education sessions on governance, cybersecurity and AI oversight
  • Succession and key-person dependency assessment

How a typical engagement runs

  1. Assess

    Interviews with directors and senior management, review of existing charters, minutes, policies and authority limits. What exists on paper is compared with what actually happens.

  2. Design

    A framework proportionate to the company, decision rights, committee structure, reporting cadence and escalation routes. Proportionality is the point; public-company machinery in a $20M business fails from disuse.

  3. Implement

    Documents drafted, system permissions aligned to the authority matrix, reporting templates built, and the people who will operate the process trained in it.

  4. Embed and review

    A first cycle observed, then an annual review. Frameworks decay when roles change, and the review is what catches the drift.

Corporate Governance Advisory across Ventura County and Los Angeles

This service is delivered on site and remotely across the firm's service area. See how it applies locally:

Corporate Governance Advisory: questions we are asked

Not answered here? Ask Javed directly

What does a corporate governance advisor actually do?

An advisor designs and recommends the arrangements through which a company is directed and controlled, decision rights, board and committee structure, reporting lines, risk appetite, and the escalation routes that carry bad news upward. The advisor does not run the company and does not independently assure that the arrangements work.

That second function belongs to internal audit, which tests whether the design operates as intended and reports to the board rather than to management. The separation exists for a reason: no one objectively audits a structure they built themselves. Ultimate responsibility for governance remains with the board either way.

We are a family business. Is this relevant to us?

Frequently more relevant than to a widely-held company, because family businesses carry a specific structural risk: the informal arrangements that work while everyone is in agreement have no defined behaviour when someone is not.

The pressure points are familiar, a second generation entering the business, a family member employed in a role they would not have been recruited into, transactions between the company and family entities, and succession that has been discussed but never documented. These are governance questions with unusually high emotional cost, and they are far cheaper to address in advance of the event that forces them.

Do we need an audit committee?

Not unless a regulator, a lender or an investor agreement requires one. What most mid-market private companies benefit from is smaller: at least one director without an executive role who reviews the financial reporting, has an independent relationship with the external auditor, and can ask management a question without it being a confrontation.

Standing up a full committee with a charter, a work plan and quarterly meetings for a company with a five-person board is usually theatre. It consumes time and produces documents nobody reads.

How do we handle a whistleblower report about a senior executive?

The determining factor is whether the process was designed before the report arrived. If the only route for a concern runs through the executive it concerns, the company will not hear about it, and when it does, the response will be improvised under pressure and will likely make the situation worse.

A workable process needs a reporting channel outside the management line, a defined non-executive recipient, a documented triage step, and a pre-agreed position on when outside investigators are engaged. This is an hour of design work that pays for itself once.

How much does a governance assessment cost?

A framework assessment and design engagement for a single-entity mid-market company generally runs four to six weeks. The variables are entity count, whether a functioning board already exists, and how much documentation is in place.

Board education sessions and audit committee support are usually retained separately on an annual basis tied to the meeting calendar, which is a considerably smaller commitment than the initial design work.

Related services

Organisations we have worked with

Three decades of audit, controls and finance leadership across banking, card, mortgage, insurance, staffing and semiconductor.

  • Diodes Incorporated
  • City National Bank
  • Robert Half
  • SMBC
  • PennyMac
  • American Express
  • Zenith Insurance
  • Capco Consulting Services
  • WebVision

Get in touch

Enquire about corporate governance advisory

A sentence or two about your situation (the standard involved, the deadline, and what has already been attempted) is enough to get a useful reply.

Have a deadline, or just a question?

Send the shape of it. The first call is diagnostic, not billed, and it regularly ends with a smaller engagement than the one you asked about.

Javed Peeran CPA Request a consultation

Answered personally, within one business day. Your details are used only to reply to you, see our privacy policy.

Talk through a corporate governance advisory engagement

Thirty years of audit, financial leadership and IT governance in one engagement, and a direct answer about scope, sequence and cost before anything is signed.

WhatsApp Us
Call Now